Subject: Re: X font library vulnerability vs. pkgsrc
To: Charles M. Hannum <abuse@spamalicious.com>
From: Steven M. Bellovin <smb@research.att.com>
List: netbsd-users
Date: 10/09/2003 16:56:18
In message <200310092047.50584.abuse@spamalicious.com>, "Charles M. Hannum" wri
tes:
>On Thursday 09 October 2003 08:38 pm, Steve Bellovin wrote:
>> It isn't clear to me from the vulnerability notice just how much needs
>> to be rebuilt.  Just some shared libraries?  Executables, too?  If the
>> latter, what about pkgsrc applications that use X?
>
>Prior to -current as of several days ago, libFS was only a static library, so 
>you'd need to rebuild anything that uses it (including the X server, I 
>think).
>


Which means that a lot of pkgsrc needs to be rebuilt.  Anyone have any 
nice scripts for determining exactly what?  (And the advisory should be 
amended to note the issue.)

		--Steve Bellovin, http://www.research.att.com/~smb